← Vulnerability feed

Vulnerability record · CVE-2026-49497 · published 10 June 2026

CVE-2026-49497: Nsa ghidra path traversal vulnerability

Nsa · Ghidra

Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu_debuglink sections before constructing file paths. Attackers can craft malicious ELF binaries with traversal sequences to probe filesystem existence and leak CRC32 hashes of arbitrary files during automatic DWARF analysis.

4.6 CVSS 4.0 Medium EPSS 0.19% · top 92.5% CWE-22 · Path traversal
4.6CVSS 4.0 base score
0.19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
14 Jul 2026Last modified by NVD

Description

Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu_debuglink sections before constructing file paths. Attackers can craft malicious ELF binaries with traversal sequences to probe filesystem existence and leak CRC32 hashes of arbitrary files during automatic DWARF analysis.

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-49497 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-22671Nsa ghidra command injection vulnerabilityGhidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when ca…EPSS 2.9%9.8CVE-2019-16941Nsa ghidra xml injection vulnerabilityNSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer i…EPSS 5.1%9.1CVE-2019-13625Nsa ghidra xml external entity (xxe) vulnerabilityNSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.EPSS 2.4%8.8CVE-2026-4946Nsa ghidra os command injection vulnerabilityGhidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary comm…EPSS 0.77%8.7CVE-2026-52758Nsa ghidra sql injection vulnerabilityGhidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries withou…EPSS 0.56%8.7CVE-2026-52754Nsa ghidra improper verification of cryptographic signature vulnerabilityGhidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-sig…EPSS 0.45%8.7CVE-2026-49498Nsa ghidra sql injection vulnerabilityGhidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double…EPSS 0.47%8.6CVE-2026-52751Nsa ghidra deserialization of untrusted data vulnerabilityGhidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated rem…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2026-49497), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.